Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT …
Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations
Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing, and product shipments. The company said the incident was detected on August …
Hackers Pose as OpenAI, Anthropic and DeepSeek to Steal Credentials and Secrets
Threat actors are impersonating web crawlers from OpenAI, Anthropic, DeepSeek, and other major organizations to scan websites for exposed credentials and sensitive configuration files, targeting misconfigured servers that may leak …
JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access
A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges. WatchTowr said its intelligence team …
21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation
Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email infrastructure. According to daily …
Hackers Abuse Real ChatGPT Links to Trick Windows Users Into Installing Malware
Windows users are being targeted through a malicious campaign that turns a ChatGPT shared link into the step of a malware infection. Rather than breaking into the AI platform, the …
WordPress Is Using AI to Find Security Flaws Before Hackers Can Exploit Them
WordPress has launched a new security effort that uses artificial intelligence to identify vulnerabilities in its core software before attackers can abuse them. The initiative comes as the project receives …
Hackers Use AI Malware to Rank and Sell Access to Compromised Corporate Networks
Hackers are using a new Windows malware framework to turn corporate break-ins into products for sale. The tool, called BraZetsu, quietly maps a victim’s systems, finds valuable business data and …
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness. While Microsoft classifies the issue as an elevation-of-privilege flaw, the …
New Windows Backdoor Stays Completely Silent Until Hackers Send a Secret Trigger
SLEEPWALKER is a newly identified Windows backdoor built to wait rather than call home. Once placed on a compromised device, it can sit inactive for an extended period, only responding …
